URL:

https://drive.google.com/file/d/1zsLt6VhcqMOtcb5evb6oBd8I0-KnKFj9/view

Full analysis: https://app.any.run/tasks/0c3dfc67-b0ac-4f70-83ba-d39bda664fae
Verdict: Malicious activity
Analysis date: February 28, 2026, 07:38:23
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
github
obfuscated-js
Indicators:
MD5:

4F96150397A84C5EB08F3BD0CE9264D9

SHA1:

3E8D378EDFEFFB4C1DE66D792A3456A38E6D6BCE

SHA256:

E32A50821BB90A700D86C7CFD4C2A91DE4D10E472C15D9269EBD25E625E9B9B4

SSDEEP:

3:N8PMMtZJuloM/GH6uBF:2AneHLBF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • NewLauncher-2.0.3-windows-x64.exe (PID: 7576)
      • NewLauncher-2.0.7-windows-ia32.exe (PID: 7172)
      • NewLauncher-2.0.3-windows-x64.exe (PID: 7412)
      • old-uninstaller.exe (PID: 6864)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • NewLauncher-2.0.3-windows-x64.exe (PID: 7576)
      • NewLauncher-2.0.7-windows-ia32.exe (PID: 7172)
      • NewLauncher-2.0.3-windows-x64.exe (PID: 7412)
      • old-uninstaller.exe (PID: 6864)
    • Get information on the list of running processes

      • NewLauncher-2.0.3-windows-x64.exe (PID: 7576)
      • cmd.exe (PID: 7900)
      • NewLauncher-2.0.7-windows-ia32.exe (PID: 7172)
      • old-uninstaller.exe (PID: 6864)
      • cmd.exe (PID: 6940)
    • Starts CMD.EXE for commands execution

      • NewLauncher-2.0.3-windows-x64.exe (PID: 7576)
      • old-uninstaller.exe (PID: 6864)
    • Application launched itself

      • NewLauncher.exe (PID: 8604)
      • NewLauncher.exe (PID: 8188)
      • NewLauncher.exe (PID: 5456)
    • Hides errors and continues executing the command without stopping

      • powershell.exe (PID: 8716)
    • Starts POWERSHELL.EXE for commands execution

      • NewLauncher-2.0.7-windows-ia32.exe (PID: 7172)
    • Kill processes via PowerShell

      • powershell.exe (PID: 4324)
    • Searches for installed software

      • NewLauncher-2.0.7-windows-ia32.exe (PID: 7172)
  • INFO

    • Application launched itself

      • msedge.exe (PID: 7220)
    • Reads the computer name

      • identity_helper.exe (PID: 8412)
      • identity_helper.exe (PID: 6060)
      • NewLauncher-2.0.3-windows-x64.exe (PID: 7576)
      • NewLauncher.exe (PID: 8912)
      • NewLauncher.exe (PID: 8904)
      • NewLauncher.exe (PID: 8604)
      • NewLauncher.exe (PID: 8188)
      • NewLauncher.exe (PID: 3424)
      • NewLauncher.exe (PID: 8480)
      • NewLauncher-2.0.7-windows-ia32.exe (PID: 7172)
      • NewLauncher.exe (PID: 5456)
      • NewLauncher.exe (PID: 5408)
      • NewLauncher.exe (PID: 8920)
      • NewLauncher.exe (PID: 8656)
    • Page contains obfuscated JavaScript

      • msedge.exe (PID: 7220)
    • Checks supported languages

      • identity_helper.exe (PID: 8412)
      • identity_helper.exe (PID: 6060)
      • NewLauncher.exe (PID: 8604)
      • NewLauncher-2.0.3-windows-x64.exe (PID: 7576)
      • NewLauncher.exe (PID: 8312)
      • NewLauncher.exe (PID: 8912)
      • NewLauncher-2.0.7-windows-ia32.exe (PID: 7172)
      • NewLauncher.exe (PID: 8904)
      • NewLauncher-2.0.3-windows-x64.exe (PID: 7412)
      • NewLauncher.exe (PID: 8188)
      • NewLauncher.exe (PID: 3424)
      • NewLauncher.exe (PID: 8480)
      • old-uninstaller.exe (PID: 6864)
      • NewLauncher.exe (PID: 5456)
      • NewLauncher.exe (PID: 5408)
      • NewLauncher.exe (PID: 8828)
      • NewLauncher.exe (PID: 8656)
      • NewLauncher.exe (PID: 8920)
    • Drops script file

      • msedge.exe (PID: 7220)
      • msedge.exe (PID: 8480)
      • NewLauncher-2.0.3-windows-x64.exe (PID: 7576)
      • NewLauncher.exe (PID: 8604)
      • powershell.exe (PID: 9124)
      • powershell.exe (PID: 8716)
      • powershell.exe (PID: 1032)
      • powershell.exe (PID: 4324)
      • NewLauncher.exe (PID: 8188)
      • powershell.exe (PID: 4312)
      • old-uninstaller.exe (PID: 6864)
      • NewLauncher-2.0.7-windows-ia32.exe (PID: 7172)
      • NewLauncher.exe (PID: 5456)
    • Reads Environment values

      • identity_helper.exe (PID: 8412)
      • identity_helper.exe (PID: 6060)
      • NewLauncher.exe (PID: 8604)
      • NewLauncher.exe (PID: 8188)
      • NewLauncher.exe (PID: 5456)
    • Creates files or folders in the user directory

      • NewLauncher-2.0.3-windows-x64.exe (PID: 7576)
      • NewLauncher.exe (PID: 8604)
      • NewLauncher.exe (PID: 8904)
      • NewLauncher-2.0.7-windows-ia32.exe (PID: 7172)
      • NewLauncher.exe (PID: 5456)
      • NewLauncher.exe (PID: 5408)
      • NewLauncher.exe (PID: 8656)
    • Manual execution by a user

      • NewLauncher.exe (PID: 8604)
      • NewLauncher-2.0.3-windows-x64.exe (PID: 7576)
      • NewLauncher-2.0.3-windows-x64.exe (PID: 7412)
      • NewLauncher.exe (PID: 8188)
      • NewLauncher.exe (PID: 5456)
    • Create files in a temporary directory

      • NewLauncher-2.0.3-windows-x64.exe (PID: 7576)
      • NewLauncher.exe (PID: 8604)
      • NewLauncher-2.0.7-windows-ia32.exe (PID: 7172)
      • NewLauncher-2.0.3-windows-x64.exe (PID: 7412)
      • old-uninstaller.exe (PID: 6864)
      • NewLauncher.exe (PID: 5456)
    • There is functionality for taking screenshot (YARA)

      • NewLauncher-2.0.3-windows-x64.exe (PID: 7576)
    • Reads security settings of Internet Explorer

      • NewLauncher-2.0.3-windows-x64.exe (PID: 7576)
      • NewLauncher-2.0.7-windows-ia32.exe (PID: 7172)
      • OpenWith.exe (PID: 4260)
      • notepad.exe (PID: 7356)
    • Creates a software uninstall entry

      • NewLauncher-2.0.3-windows-x64.exe (PID: 7576)
      • NewLauncher-2.0.7-windows-ia32.exe (PID: 7172)
    • Checks proxy server information

      • NewLauncher.exe (PID: 8604)
      • NewLauncher.exe (PID: 8188)
      • NewLauncher.exe (PID: 5456)
    • Reads the machine GUID from the registry

      • NewLauncher.exe (PID: 8604)
      • NewLauncher.exe (PID: 8188)
      • NewLauncher.exe (PID: 5456)
      • NewLauncher.exe (PID: 5408)
    • Process checks computer location settings

      • NewLauncher.exe (PID: 8312)
      • NewLauncher.exe (PID: 8604)
      • NewLauncher.exe (PID: 8188)
      • NewLauncher.exe (PID: 5456)
      • NewLauncher.exe (PID: 8828)
    • Reads product name

      • NewLauncher.exe (PID: 8604)
      • NewLauncher.exe (PID: 8188)
      • NewLauncher.exe (PID: 5456)
    • Gets the execution policy for the powershell session

      • NewLauncher-2.0.7-windows-ia32.exe (PID: 7172)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 4260)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
241
Monitored processes
94
Malicious processes
1
Suspicious processes
3

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs newlauncher-2.0.3-windows-x64.exe no specs msedge.exe no specs cmd.exe no specs conhost.exe no specs tasklist.exe no specs find.exe no specs msedge.exe no specs newlauncher.exe newlauncher.exe no specs newlauncher.exe newlauncher.exe no specs msedge.exe no specs msedge.exe no specs newlauncher-2.0.7-windows-ia32.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs newlauncher-2.0.3-windows-x64.exe no specs powershell.exe no specs conhost.exe no specs newlauncher.exe newlauncher.exe no specs newlauncher.exe no specs powershell.exe no specs conhost.exe no specs old-uninstaller.exe no specs cmd.exe no specs conhost.exe no specs tasklist.exe no specs find.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs newlauncher.exe newlauncher.exe no specs newlauncher.exe newlauncher.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs openwith.exe no specs notepad.exe no specs msedge.exe no specs msedge.exe no specs newlauncher.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
204"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=6 --always-read-main-dll --field-trial-handle=3580,i,6133304708389031251,16236961098957807002,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=3688 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
572"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3552,i,6133304708389031251,16236961098957807002,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=3768 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1032"C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe" -C "if ((Get-ExecutionPolicy -Scope Process) -eq 'Restricted') { exit 1 } else { exit 0 }"C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeNewLauncher-2.0.7-windows-ia32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1132"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2336,i,6133304708389031251,16236961098957807002,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=2332 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1272"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=4928,i,6133304708389031251,16236961098957807002,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=4972 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1272\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2368\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2420"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=7468,i,6133304708389031251,16236961098957807002,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=7360 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2936"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=51 --always-read-main-dll --field-trial-handle=8420,i,6133304708389031251,16236961098957807002,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=8444 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2940"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5384,i,6133304708389031251,16236961098957807002,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=5448 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
31 514
Read events
31 442
Write events
34
Delete events
38

Modification events

(PID) Process:(7576) NewLauncher-2.0.3-windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\8cc7a8e8-ae96-5e65-9129-5a3f65e308e7
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\Programs\NewLauncher
(PID) Process:(7576) NewLauncher-2.0.3-windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\8cc7a8e8-ae96-5e65-9129-5a3f65e308e7
Operation:writeName:KeepShortcuts
Value:
true
(PID) Process:(7576) NewLauncher-2.0.3-windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\8cc7a8e8-ae96-5e65-9129-5a3f65e308e7
Operation:writeName:ShortcutName
Value:
NewLauncher
(PID) Process:(7576) NewLauncher-2.0.3-windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\8cc7a8e8-ae96-5e65-9129-5a3f65e308e7
Operation:writeName:DisplayName
Value:
NewLauncher 2.0.3
(PID) Process:(7576) NewLauncher-2.0.3-windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\8cc7a8e8-ae96-5e65-9129-5a3f65e308e7
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Local\Programs\NewLauncher\Uninstall NewLauncher.exe" /currentuser
(PID) Process:(7576) NewLauncher-2.0.3-windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\8cc7a8e8-ae96-5e65-9129-5a3f65e308e7
Operation:writeName:QuietUninstallString
Value:
"C:\Users\admin\AppData\Local\Programs\NewLauncher\Uninstall NewLauncher.exe" /currentuser /S
(PID) Process:(7576) NewLauncher-2.0.3-windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\8cc7a8e8-ae96-5e65-9129-5a3f65e308e7
Operation:writeName:DisplayVersion
Value:
2.0.3
(PID) Process:(7576) NewLauncher-2.0.3-windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\8cc7a8e8-ae96-5e65-9129-5a3f65e308e7
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\Programs\NewLauncher\NewLauncher.exe,0
(PID) Process:(7576) NewLauncher-2.0.3-windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\8cc7a8e8-ae96-5e65-9129-5a3f65e308e7
Operation:writeName:Publisher
Value:
NewLauncher
(PID) Process:(7576) NewLauncher-2.0.3-windows-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\8cc7a8e8-ae96-5e65-9129-5a3f65e308e7
Operation:writeName:NoModify
Value:
1
Executable files
0
Suspicious files
3
Text files
6
Unknown types
1 822

Dropped files

PID
Process
Filename
Type
7220msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RFc1283.TMP
MD5:
SHA256:
7220msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
7220msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RFc1283.TMP
MD5:
SHA256:
7220msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RFc1283.TMP
MD5:
SHA256:
7220msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RFc1293.TMP
MD5:
SHA256:
7220msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
7220msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
7220msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
7220msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RFc1283.TMP
MD5:
SHA256:
7220msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
535
TCP/UDP connections
388
DNS requests
220
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7792
msedge.exe
GET
200
150.171.27.11:443
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
US
295 b
whitelisted
7792
msedge.exe
OPTIONS
200
142.251.143.106:443
https://ogads-pa.clients6.google.com/$rpc/google.internal.onegoogle.asyncdata.v1.AsyncDataService/GetAsyncData
US
whitelisted
7792
msedge.exe
GET
200
150.171.27.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:xuGnTEE4ofwi-6QsyFQK5iA8wElxPZ-uB-_bJdIb8QM&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
binary
101 b
whitelisted
7248
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
7792
msedge.exe
GET
200
142.251.141.110:443
https://drive.google.com/auth_warmup
US
whitelisted
7792
msedge.exe
GET
302
142.251.141.110:443
https://drive.google.com/drivesharing/clientmodel?id=1zsLt6VhcqMOtcb5evb6oBd8I0-KnKFj9&foreignService=texmex&authuser=0&origin=https%3A%2F%2Fdrive.google.com
US
whitelisted
7792
msedge.exe
GET
200
52.123.243.84:443
https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=67&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1772264309&lafgdate=0
US
4.47 Kb
whitelisted
7792
msedge.exe
OPTIONS
200
172.217.16.206:443
https://play.google.com/log?format=json&hasfast=true
US
whitelisted
7792
msedge.exe
GET
200
104.18.23.222:443
https://copilot.microsoft.com/c/api/user/eligibility
US
25 b
whitelisted
7792
msedge.exe
GET
200
142.251.141.110:443
https://drive.google.com/file/d/1zsLt6VhcqMOtcb5evb6oBd8I0-KnKFj9/view
US
binary
140 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
5100
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5276
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
48.192.1.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
20.190.159.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7248
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
135.236.137.174:443
licensing.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
7792
msedge.exe
150.171.27.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
  • 20.73.194.208
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.65
whitelisted
google.com
  • 142.251.127.101
  • 142.251.127.113
  • 142.251.127.139
  • 142.251.127.102
  • 142.251.127.138
  • 142.251.127.100
whitelisted
client.wns.windows.com
  • 172.211.123.248
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.159.73
  • 40.126.31.130
  • 40.126.31.69
  • 20.190.159.71
  • 20.190.159.75
  • 40.126.31.3
  • 20.190.159.4
  • 20.190.159.68
  • 40.126.31.2
  • 40.126.31.129
  • 40.126.31.0
  • 20.190.159.64
whitelisted
ocsp.digicert.com
  • 184.30.131.245
  • 162.159.142.9
  • 172.66.2.5
whitelisted
licensing.mp.microsoft.com
  • 135.236.137.174
whitelisted
self.events.data.microsoft.com
  • 20.189.173.26
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
config.edge.skype.com
  • 52.123.243.84
  • 52.123.243.70
  • 52.123.243.215
  • 52.123.243.82
whitelisted

Threats

PID
Process
Class
Message
5100
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
7792
msedge.exe
Potentially Bad Traffic
ET INFO PE EXE or DLL Windows file download HTTP
7792
msedge.exe
Misc activity
ET INFO EXE - Served Attached HTTP
2232
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
No debug info